Privacy and your data
What we store
| Data | Why | Where it comes from |
|---|---|---|
| Product and variant records | To price the widget and populate the plan builder | Your Shopify catalogue |
| Customer name, email, phone, address | To send notifications and sign customers into the portal | Shopify, with your approval |
| Subscription contracts and their history | To run the dashboard and the portal | Shopify |
| Orders linked to subscriptions | To show charge history | Shopify |
| Your plan configuration | It is the app | You |
What we never store
Card numbers, bank details or any payment instrument. Payment methods are vaulted by Shopify. We can ask Shopify whether a contract has a usable payment method; we cannot see what it is. When a customer updates their card they do it on a page Shopify hosts.
We also do not store passwords. Portal sign-in uses a one-time code sent to the customer's email.
Protected customer fields
Shopify treats customer name, email, phone and address as protected customer data, approved separately from ordinary app permissions. We request them because:
- Email — renewal reminders, failed-payment notices, and portal sign-in codes. Without it there is no way to reach a subscriber at all.
- Name — addressing those messages.
- Phone — WhatsApp notifications, where enabled.
- Address — shipping the subscription.
If approval has not been granted, the app degrades rather than breaks: subscriptions still bill, because Shopify handles that. Notifications and portal sign-in do not work, because there is nowhere to send to. We store only what Shopify actually returns — a withheld field is left absent rather than overwritten with a blank, so nothing already known is erased.
Encryption
- In transit: everything over HTTPS.
- At rest: the database is encrypted, and access tokens are encrypted again at the application level with a separate key, so a database copy alone does not yield working credentials.
Retention and deletion
We keep your data while the app is installed.
When you uninstall, Shopify notifies us and we delete your shop's data within 48 hours, as Shopify requires. Your subscription contracts stay on your Shopify store — they are Shopify's objects and they belong to you.
Export anything you want to keep before uninstalling.
Customer deletion requests. Shopify forwards GDPR-style requests to us and we act on them:
- Customer data request — we return everything we hold on that customer
- Customer redact — we delete their personal data, keeping only anonymised financial records where law requires
- Shop redact — we delete the entire shop's data
Who can see your data
Your data is yours. We do not sell it, share it with advertisers, or use it to train anything.
Access within our team is limited to support and engineering staff who need it to help you, and is logged.
Sub-processors
| Provider | Purpose |
|---|---|
| Amazon Web Services | Hosting and the database |
| Amazon SES | Transactional email |
| Your WhatsApp Business provider | WhatsApp messages, if you enable them |
Your obligations
You are the data controller for your customers' data; we are a processor acting on your instructions. You should have a privacy policy telling your customers that a subscription app processes their data on your behalf. Shopify requires this of all merchants.
Some jurisdictions require advance notice before charging a recurring payment — see Notifications for renewal reminders.